Getting on a Zoom call is an act of trust — and that trust nearly became a liability. Researchers at digital defense firm A Security disclosed a set of vulnerabilities in Zoom that could have let anyone on a call quietly take over another participant’s device. No warning, no click, no interaction required from the victim.
The catch that makes this one genuinely unsettling: it applied to anyone on a call that involved screen sharing, whether you were a participant or the host. And it wasn’t platform-specific. The flaw affected every operating system Zoom supports — Windows, macOS, Linux, iOS, and Android.
Here’s where the story gets even more modern. A Security says the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and build a working attack.
“Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Now people can reach the same results with under 20 prompts.” His bigger worry isn’t the bug itself, but the trend: “the democratization of these capabilities — the barrier to entry is dropping rapidly.”
The vulnerabilities lived in the protocol that handles real-time annotation during screen sharing — the feature that lets people scribble arrows and highlights over a shared window. That’s not an accident of the AI’s targeting. Like seasoned human bug hunters, the AI systems zeroed in on convoluted, obscure functions because that’s exactly where overlooked mistakes tend to hide. In proprietary, closed-source software, an esoteric-but-complex feature like annotation gets less public scrutiny than the core code, making it fertile ground for flaws.
The practical worst case is grim. “If you just get on a Zoom with us, we can take over your device,” cofounder Yossi Torati told WIRED — over a call that was, fittingly, hosted on Microsoft Teams. From there, an attacker on a call with someone at a company could seize their computer and credentials, then move laterally across the entire enterprise. Given how often Zoom is used for webinars, events, and semipublic gatherings where people don’t vet who else is dialed in, that’s a wide-open attack surface.
The good news arrives with the bad. Zoom issued a security advisory on Tuesday and has begun rolling out fixes, patching the flaw on both the server side and the client side — meaning both Zoom’s own infrastructure and the apps running on your devices. Zoom did not respond to WIRED’s requests for comment on the findings.
If you use Zoom, the takeaway is simple: update your client now. The deeper takeaway is harder to patch. Security has long been described as a cat-and-mouse game, but with AI-assisted bug hunting proliferating, that careful back-and-forth is turning into a flat-out sprint.